What it is
WebRTC lets pages open peer-to-peer connections for calls and file transfer. To connect, the browser asks a STUN server "what address do you see me from?" — and hands the answer to the page.
How websites read it
const pc = new RTCPeerConnection({ iceServers: [{ urls: 'stun:stun.example.net' }] });
pc.createDataChannel('x'); pc.createOffer().then((o) => pc.setLocalDescription(o));
pc.onicecandidate = (e) => console.log(e.candidate?.candidate); // "... srflx ... 198.51.100.24"No permission is needed for candidate gathering. Server-reflexive (srflx) candidates carry your public address; host candidates carry LAN addresses, masked behind mDNS names in modern browsers.
Why it identifies you
A proxy configured in the browser only covers HTTP. STUN packets are plain UDP: they leave through your real connection and come back with your real IP.
How risk-control systems use it
Sites compare the WebRTC address with the address the HTTP request came from. A mismatch is one of the highest-confidence proxy signals — it needs no database, just two strings.
Common mistakes
Disabling WebRTC entirely (a hole where a value should be); leaving the real IP visible; extensions that block STUN but not TURN.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
CustomModes: off, auto (replace with the proxy exit IP), manual, real, disable UDP. Auto is the default — WebRTC keeps working and agrees with the HTTP IP.
Check yours
Jump to this signal in your scan results.